Centralized exchange in Sao Tome and Principe
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Sao Tome and Principe with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD) under Lei n.º 10/2012 and Lei n.º 7/2020 — identification and verification of individuals (name, address, date of birth, nationality, unique ID) and legal entities
- Beneficial ownership identification and verification required
- Ongoing monitoring of transactions throughout the business relationship
- Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusually large transactions, and transactions with no apparent economic purpose
- Suspicious Transaction Reporting (STR) to the Unidade de Informação Financeira (UIF) — promptly, regardless of amount, with no tipping-off
- Record-keeping: customer identification data, transaction records (amount, currency, date, parties), and business correspondence — retention periods follow general AML law
- Internal AML/CFT policies, controls, and training required
- Simplified Due Diligence (SDD) permitted only in low-risk circumstances determined by the obliged entity
Key Restrictions
- If the exchange facilitates virtual-to-fiat (STN) conversion, it may be deemed to require a banking license or payment service provider license from BCSTP
- No specific VASP or crypto custody licensing regime exists — operators relying on pure crypto-to-crypto activity operate in a regulatory grey area
- If the exchange takes custody of user assets and those assets are considered 'funds' or 'property' under existing law, broader financial services regulations may apply
- Local incorporation, physical office, local management/staff, and a compliance officer required for any traditional financial license path
- No specific rules mandate segregation of client digital assets; asset-protection expectations are informal and uncodified
- Travel Rule (FATF Recommendation 16) not explicitly adopted — no regulatory guidance on originator/beneficiary information requirements for VASP transfers
Key Risks
- Regulatory grey area: pure crypto-to-crypto exchange may avoid licensing but faces uncertainty about future regulatory action
- BCSTP has publicly warned that cryptocurrencies are not legal tender and warned about risks — negative regulatory posture
- No specific qualified custodian or cold-storage mandates — operator bears full risk of loss/theft without legal safe harbors
- If fiat on/off-ramps are used, the operator could be found to be conducting unlicensed financial services activity with serious penalties
- FATF/GIABA member status creates pressure to implement VASP licensing and Travel Rule — regulatory landscape could shift rapidly
- Extremely small market and limited enforcement precedent make it difficult to predict regulatory response to any specific operating model
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Neither a dedicated Registration nor Licensing Regime for VASPs: As of the latest information, STP does not have a specific regime for registering or licensing virtual asset service providers.
Implication: Companies operating solely with crypto-to-crypto transactions might operate in a regulatory grey area from a specific licensing perspective. However, any interaction with traditional fiat currency or the broader financial system would likely bring them under the purview of existing financial regulations.
Cryptocurrency Exchanges (especially those dealing with fiat):
If an exchange facilitates the exchange of virtual assets for fiat currency (e.g., STN - Sao Tome Dobra) or vice versa, and offers services akin to traditional banking or money remittance, it might be deemed to be conducting activities that require a banking license or a payment service provider license from the Banco Central de São Tomé e Príncipe (BCSTP).
Pure crypto-to-crypto exchanges might not require a specific license yet, but they would still be subject to AML/CFT obligations if they deal with "funds" or "assets" in a broad sense.
If a custody provider holds virtual assets on behalf of clients, especially if these assets are considered "funds" or "property" under existing laws, they might fall under broader financial services regulations. There is no specific "crypto custody" license. Depending on the nature of the assets and the services, they might potentially be seen as requiring an investment services license or, in some interpretations, even a form of banking license if they hold significant client assets.
AML/KYC (Anti-Money Laundering/Know Your Customer): This is the most crucial and universally applicable requirement, even in the absence of specific crypto licensing. STP has AML/CFT legislation in line with international standards (FATF recommendations). Any entity dealing with funds, regardless of their nature (fiat or virtual assets), would be subject to:
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures.
Suspicious Transaction Reporting (STR) to the Financial Information Unit (FIU) of Sao Tome and Principe.
Local Presence: For any traditional financial license, a significant local presence is typically required, including:
Local management and staff, including a compliance officer.
There are no specific licensing requirements for cryptocurrency custodians in Sao Tome and Principe.
However, any entity engaging in financial services (broadly defined) or activities that could be interpreted as traditional financial intermediation might fall under existing general financial services laws and require a license from the Banco Central de São Tomé e Príncipe (BCSTP) or other relevant authorities. This would be a matter of interpretation, as these laws predate crypto.
There are no specific rules mandating the segregation of client digital assets for cryptocurrency custodians.
In the absence of specific crypto legislation, general principles of fiduciary duty and client asset protection (from traditional finance) might be informally expected, but they are not codified for digital assets.
There are no specific mandates regarding the use of cold storage or other particular security measures for digital assets.
Lei n.º 10/2012, de 23 de Agosto (Law No. 10/2012, of August 23): This is the foundational law for the Prevention and Combat of Money Laundering and Terrorism Financing. It establishes the general framework for AML/CFT obligations for financial and non-financial institutions.
Lei n.º 7/2020, de 16 de Julho (Law No. 7/2020, of July 16): This law amended and republished Law No. 10/2012. Amendments typically reflect updated FATF recommendations and often broaden the scope of obliged entities or strengthen specific requirements (like beneficial ownership or risk-based approaches), which would implicitly apply to emerging sectors like virtual assets.
Identification and Verification of Customers:
Beneficial Ownership: Identifying and taking reasonable measures to verify the identity of the beneficial owner(s) of the customer, including natural persons who ultimately own or control the customer, or the natural person on whose behalf a transaction is being conducted.
Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the obliged entity’s knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Enhanced Due Diligence (EDD): Applying enhanced measures for higher-risk customers, relationships, or transactions, such as:
Customers from high-risk jurisdictions identified by FATF or national authorities.
Complex or unusually large transactions.
Transactions with no apparent economic or lawful purpose.
Simplified Due Diligence (SDD): Permitted in specific, low-risk circumstances, provided that the obliged entity has determined the relationship or transaction presents a low risk of money laundering or terrorist financing.
Report Suspicious Transactions: Report to the Financial Intelligence Unit (UIF) any transaction, attempted transaction, or activity that they know, suspect, or have reasonable grounds to suspect involves funds derived from criminal activity or is related to terrorism financing, regardless of the amount.
Timeliness: Reports must be made promptly.
No Tipping-Off: Obliged entities, their directors, officers, and employees are prohibited from disclosing to the customer or to third parties that an STR is being or has been submitted.
Customer Identification Data: All records obtained through CDD procedures (e.g., copies of identification documents, verification data).
Transaction Records: Details of all domestic and international transactions, including the amount, currency, date, and parties involved (originator and beneficiary information).
Business Correspondence: Relevant correspondence regarding business relationships.
Unidade de Informação Financeira (UIF) – Financial Intelligence Unit:
Banco Central de São Tomé e Príncipe (BCSTP) – Central Bank of São Tomé and Príncipe:
No specific legislation or regulatory guidance explicitly implementing the FATF Travel Rule for VASPs has been publicly identified.
Sao Tome and Principe's primary anti-money laundering and combating the financing of terrorism (AML/CFT) law is likely Lei n.º 1/2012, de 27 de Junho (Law No. 1/2012, of June 27). This law predates the FATF's updated Recommendation 15 and 16 (which introduced the Travel Rule for VASPs in June 2019) and therefore does not include specific provisions for virtual assets or the Travel Rule.
The Banco Central de São Tomé e Príncipe (BCSTP), the central bank and financial regulator, has issued warnings regarding cryptocurrencies. For example, Comunicado n.º 001/2022 (April 2022) clarified that cryptocurrencies are not legal tender in Sao Tome and Principe and warned about the risks associated with their use. This indicates awareness of virtual assets but does not constitute a regulatory framework for VASPs or the Travel Rule.
Not applicable, as the Travel Rule has not been explicitly adopted or implemented.
Small Financial Market: Sao Tome and Principe has a very small economy and financial sector. The adoption and prevalence of complex cryptocurrency operations that would warrant significant enforcement actions (like those seen in major financial hubs) are extremely limited.
Developing Regulatory Framework: Many smaller nations are still in the early stages of developing specific regulations for cryptocurrencies. Their primary focus tends to be on general financial stability, anti-money laundering (AML), and countering the financing of terrorism (CFT) within traditional banking.
Primary Regulator: The main financial regulator in Sao Tome and Principe is the Banco Central de São Tomé e Príncipe (BCSTP). Their pronouncements on digital currencies typically revolve around issuing warnings to the public about the risks associated with cryptocurrencies, rather than specific enforcement actions against entities. They often emphasize that cryptocurrencies are not legal tender.
Lack of Public Reporting: Even if smaller, localized enforcement actions (e.g., against a very small local operation or individual) were to occur, they are rarely reported beyond national borders or in a manner that is easily accessible internationally.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange can operate in São Tomé and Príncipe only if it either restricts itself to pure crypto-to-crypto activities in a regulatory grey area or, if offering fiat on/off-ramps, obtains a banking or payment-service license from BCSTP (a high-burden process requiring local incorporation, physical presence, and local management), and in all cases must comply with general AML/CFT obligations under Lei n.º 10/2012 / Lei n.º 7/2020, while the Travel Rule has not been implemented and no specific custody or asset-segregation rules exist.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?